* Patches from Microsoft, Apple, Gentoo, others * Beware e-mail virus, W32/Loosky-S * Interview with Ilfak Guilfanov, author of 'unauthorized' WMF patch
Today’s bug patches and security alerts:
[Editor’s note: Microsoft released this patch shortly after we sent our Thursday newsletter’s deadline.]
Microsoft rushes out patch for WMF flaw, 01/05/06
Amid controversy and customer demand surrounding a flaw in its Windows operating system, Microsoft on Thursday abandoned its announced timetable for supplying a fix and rushed a patch onto its Web site to correct a problem that could allow a hacker to gain control over desktops or servers.
http://www.networkworld.com/go2/0109bug1a.html
Microsoft advisory:
https://www.microsoft.com/technet/security/bulletin/ms06-001.mspx
Related CERT advisory:
http://www.us-cert.gov/cas/techalerts/TA06-005A.html
**********
Apple releases AirPort firmware update
According to an advisory from Apple, “A malicious network attacker that can generate specially crafted packets may be able to cause an AirPort base station’s network interface to stop responding normally, resulting in a denial-of-service. This update addresses the issue by discarding the malformed packets.” For more, go to:
https://docs.info.apple.com/article.html?artnum=303072
**********
New HylaFAX update available
A number of vulnerabilities have been found in HylaFAX, a system for sending and receiving faxes and alphanumeric pages for Unix. The most serious of the flaws could be exploited to run arbitrary commands on the affected machine. For more, go to:
https://bugs.hylafax.org/bugzilla/show_bug.cgi?id=682
https://bugs.hylafax.org/bugzilla/show_bug.cgi?id=719
Related patch from Gentoo:
https://security.gentoo.org/glsa/glsa-200601-03.xml
**********
HP releases fix for HP-UX users running xterm Local
A local user could exploit a flaw in the xterm utility for HP-UX to gain unauthorized access to the affected machine. For more and to download the correct patch, login to the HP IT Resource Center:
**********
iDefense warns of multiple flaws in BlueCoat WinProxy
A number of vulnerabilities have been found in BlueCoat WinProxy, an Internet sharing proxy, according to iDefense. Two flaws could be exploited in denial-of-service attacks against the affected machine. A third flaw could be exploited to cause a buffer overflow and to run arbitrary code. For more, go to:
Blue Coat WinProxy Telnet DoS Vulnerability:
http://www.networkworld.com/go2/0109bug1b.html
Blue Coat WinProxy Remote DoS Vulnerability:
http://www.networkworld.com/go2/0109bug1c.html
Blue Coat Systems WinProxy Host Header Stack Overflow Vulnerability:
http://www.networkworld.com/go2/0109bug1d.html
**********
Recent updates from Gentoo:
KPdf, KWord (multiple buffer overflows):
http://security.gentoo.org/glsa/glsa-200601-02.xml
VMware Workstation (NAT flaw, code execution):
http://security.gentoo.org/glsa/glsa-200601-04.xml
**********
Recent patches from Mandriva:
poppler (multiple buffer overflows):
https://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:003
pdftohtml (multiple buffer overflows):
https://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:004
xpdf (multiple buffer overflows):
https://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:005
gpdf (multiple buffer overflows):
https://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:006
apache2 (cross-scripting attack):
https://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:007
**********
Recent fixes from Ubuntu:
blender (input validation, code execution):
http://www.networkworld.com/go2/0109bug1e.html
nbd-server (code execution, root privileges):
http://www.networkworld.com/go2/0109bug1f.html
xpdf (multiple buffer overflows):
http://www.networkworld.com/go2/0109bug1g.html
sudo (privilege escalation):
http://www.networkworld.com/go2/0109bug1h.html
**********
Today’s roundup of virus alerts:
Troj/Stinx-K — A backdoor Trojan that installs itself as “smsogx32.exe” in the Windows System folder. No word on how the backdoor is access (HTTP, IRC or specific port). (Sophos)
W32/IRCBot-BR — As the name implies, this is a backdoor bot that allows access to the infected host via IRC. It’s installed as “
Troj/Bancban-NI — A password-stealing Trojan that drops “system32.exe” in the Windows and Windows System directories. It sends its bounty to remote locations. (Sophos)
W32/Rbot-BHT — A new Rbot backdoor Trojan that spreads through network shares and installs “MStools1.exe” in the Windows System folder. It allows attackers to gain access to the infected system through IRC. (Sophos)
Troj/BagleDl-AO — A virus that spreads through network shares, dropping “anti_troj.exe” in the Windows System folder and opening the image “ntimage.gif”. It tries to download additional malicious code from pre-defined URLs. (Sophos)
Troj/Zlob-CD — This Trojan is designed to download additional malicious code from remote sites. It drops a number of files on the infected host, including “mscornet.exe”, “mssearchnet.exe” and “nvctrl.exe”. (Sophos)
Troj/Zlob-CE — Works in a similar fashion to Zlob-CD above, but tries to use more random names for its infected files. (Sophos)
Troj/Bckdr-E — A backdoor Trojan that installs itsefl as “Server2.0.exe” in the Windows folder. No word on how the backdoor is accessed. (Sophos)
Troj/Lewor-U — This Trojan attempts to terminate certain system processes and download/install additional malicious code from remote sites. It drops “niw.exe” in the Windows folder and “impai.exe” in the System folder. (Sophos)
Troj/Mainzz-F — A virus that is used to drop malware on the infected host. It spreads through network shares by exploiting the Windows LSASS vulnerability. (Sophos)
W32/Bagle-BP — This Bagle variant spreads through an e-mail message and installs “wind2ll2.exe” in the Windows System folder. The infected e-mail message will have a Happy New Year-related subject line. (Sophos)
W32/Loosky-S — A virus that spreads through e-mail and can be used for a number of malicious purposes. It spreads through message entitled “Your mail Account is Suspended” with an attachment called “acc_inf19.exe”. When run, it drops “sachostx.exe” in the Windows System folder and can be used to steal banking username and passwords, among other things. (Sophos)
**********
From the interesting reading department:
Interview with Ilfak Guilfanov, author of ‘unauthorized’ WMF patch
SecuriTeam blogs has posted an interview with Ilfak Guilfanov (author of the interim fix for the WMF vulnerability) about all things
WMF.




